North Korean hackers Andariel appear to be linked to the Play ransomware operation, according to new research.
A report from Palo Alto Networks and Unit 42 researchers claims that the Andariel group may be either an affiliate of the Play gang or acting as an initial access broker (IAB), facilitating the deployment of malware on a network it has already compromised.
The Andariel hackers are a state-run hacking group believed to be affiliated with North Korea's Reconnaissance General Bureau, a military intelligence agency. In 2019, the US imposed sanctions on North Koreans Lazarus, Bluenoroff, and Andariel for their attacks on US organizations.
See also: PSAUX ransomware attack targets 22,000 CyberPanel instances

The group typically carries out espionage and money-launderingthat help finance North Korean operations. The hackers have also been linked to ransomware operations in the past. In 2022, Kaspersky said Andariel deployed the Maui ransomware in attacks targeting Japan, Russia, Vietnam, and India.
The US government came to the same conclusion, offering $10,000,000 for any information about Rim Jong Hyok, a member of the group, who was responsible for ransomware attacks on critical infrastructure and healthcare organizations in the US.
How North Korean hackers Andariel are connected to Play ransomware
In September 2024, while responding to a Play ransomware attack , Unit 42 discovered that Andariel was behind the breach of its client's network . The breach had taken place in late May 2024.
See also: Fog and Akira ransomware compromise corporate networks via SonicWall VPN
The attackers gained initial access through a compromised user account and then extracted registry dumps and deployed Mimikatz to steal credentials.
They then developed the open-source pentesting suite Sliver for command and control (C2) beaconing and the custom info-stealing malware, DTrack.
In the following months, the hackers strengthened their network presence, creating malicious services and Remote Desktop Protocol (RDP) sessions and removing protection tools.
However, on September 5, the PLAY ransomware encryptor was executed on the network to encrypt devices. Researchers believe that the presence of hackers and the deployment of Play ransomware on the same network is not a coincidence.
Initially, they noticed that the same account was used for initial access, tool usage, lateral movement, privilege escalation, and EDR solution uninstallation. The same account led to the deployment of the Play ransomware.
Additionally, Sliver C2 communication stopped shortly before the ransomware was deployed.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Russian court sentences four members of REvil Ransomware gang
Finally, Play ransomware tools, including TokenPlayer and PsExec, were found in C:\Users\Public\Music, matching common tactics observed in previous attacks.
However, researchers are unsure whether Andariel acted as an accomplice to the Play ransomware or if they compromised the client's network and sold access to the ransomware gang.
Ransomware protection
Back up your data: One of the most effective ways to protect yourself from a attack is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.

Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest security and software updates to prevent any vulnerabilities that could be exploited by ransomware.
Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.
Use antivirus software: Installing reputable antivirus software on your devices can help you detect and prevent attacks . Be sure to update your antivirus software to ensure it is equipped to handle new threats.
See also: Ransomware gangs use LockBit's notoriety to pressure victims
Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.
Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.
Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to attacks.
Source: www.bleepingcomputer.com
